Arbitrary Command Execution Vulnerability in Wavlink AC3000 Router
CVE-2024-39604
9CRITICAL
What is CVE-2024-39604?
A vulnerability exists in the Wavlink AC3000 M33A8 router that allows an attacker to execute arbitrary commands through the update_filter_url.sh functionality. By sending a specially crafted HTTP request, an attacker can exploit this flaw to execute commands on the device, potentially leading to a full compromise. The vulnerability is susceptible to man-in-the-middle attacks, emphasizing the need for users to ensure the security of their network traffic.
Affected Version(s)
Wavlink AC3000 M33A8.V5030.210505